Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 48 additions & 0 deletions .ngit/act/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,9 @@ jobs:
- name: Schema lint
run: node tests/contract/js-schema-lint.mjs

- name: Doc-facts contract (docs that state facts must match the code)
run: python3 tests/contract/check-docs-facts.py

- name: Setup-marker ordering (roll-back safety)
run: |
# Offline (no router, no SDK, no network): the setup script's version
Expand Down Expand Up @@ -195,3 +198,48 @@ jobs:
run: python3 tests/contract/check-mirror-sync.py
- name: Stale import path check
run: python3 tests/contract/check-import-paths.py

packaging-suites:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- name: Packaging and uci-defaults shell suites (the full set)
run: |
# The release-check packaging leg, run per PR: 17 of these suites
# were lane-absent, which is how #648's class (rebrand-gutter red)
# and #663's class (committed conflict markers) reached main.
fail=0
for t in tests/packaging/*_test.sh tests/uci-defaults-*_test.sh; do
echo "== $t"
if ! bash "$t"; then
echo "FAILED: $t" >&2
fail=1
fi
done
exit $fail

hygiene:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- name: No unresolved conflict markers in the tracked tree
run: |
# Would have caught the #663 residue (markers committed through a
# rebase) before merge. Anchored to the marker-plus-space shape so
# prose and base64 never trip it.
if git grep -nE '^(<{7} |>{7} )' -- .; then
echo "ERROR: unresolved conflict markers are committed" >&2
exit 1
fi
echo "ok: no conflict markers"

release-check-fast:
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: src/go.mod
- name: Fast release-check on main (conformance + repro skipped)
run: make release-check-fast VERSION="$(cat VERSION)"
9 changes: 8 additions & 1 deletion Makefile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
.PHONY: portal-build reproducibility-test reproducibility-variance go-battery release-check
.PHONY: portal-build reproducibility-test reproducibility-variance go-battery release-check release-check-fast

# Canonical pre-PR Go gate across ALL 16 modules (src/ is a multi-module
# tree: `go ... ./...` from src/ alone covers only the root module).
Expand All @@ -17,6 +17,13 @@ go-battery:
release-check:
@bash scripts/release-check.sh "$(VERSION)"

# The per-push shape: every cheap leg of release-check (battery, deps,
# contract, packaging, the three invariant groups, version consistency)
# with reproducibility and conformance skipped — what CI runs on main.
release-check-fast:
@TOLLGATE_RELEASE_CHECK_REPRO=none TOLLGATE_RELEASE_CHECK_SKIP_CONFORMANCE=1 \
bash scripts/release-check.sh "$(VERSION)"

portal-build:
@bash packaging/portal-build.sh

Expand Down
11 changes: 10 additions & 1 deletion scripts/release-check.sh
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,10 @@
# subset instead of skipping it when docker/PRTA is unavailable (the
# release manager sets this on the machine that owns the lane).
# TOLLGATE_RELEASE_CHECK_REPRO=none skip the reproducibility build
# TOLLGATE_RELEASE_CHECK_SKIP_CONFORMANCE=1 skip the conformance lane
# (the make release-check-fast profile sets both: go-battery, deps,
# contract, packaging, the invariant groups and version consistency in
# one pass — the per-push shape of the gate).
# (default: binaries x86_64 — the cheap leg; run `make
# reproducibility-test T=... ARCH=...` for the full matrix).
set -u
Expand Down Expand Up @@ -62,8 +66,9 @@ run_contract() {
local ok=0
node tests/contract/js-schema-lint.mjs >"$tmpdir/contract.log" 2>&1 || ok=1
bash tests/contract/build-purity.sh >>"$tmpdir/contract.log" 2>&1 || ok=1
python3 tests/contract/check-docs-facts.py >>"$tmpdir/contract.log" 2>&1 || ok=1
if [ "$ok" = 0 ]; then
record "Contract" PASS "schema lint + build purity"
record "Contract" PASS "schema lint + build purity + doc facts"
else
record "Contract" FAIL "see $tmpdir/contract.log"
fi
Expand Down Expand Up @@ -99,6 +104,10 @@ run_invariant() { # run_invariant <label> <dir> <go test args...>
}

run_conformance() {
if [ "${TOLLGATE_RELEASE_CHECK_SKIP_CONFORMANCE:-0}" = 1 ]; then
record "Conformance (fast subset)" SKIP "disabled by env (fast mode)"
return
fi
if ! command -v docker >/dev/null 2>&1; then
if [ "${TOLLGATE_RELEASE_CHECK_CONFORMANCE:-0}" = 1 ]; then
record "Conformance (fast subset)" FAIL "docker unavailable but required"
Expand Down